CyberzSOC

Publication detail
← Back to advisories & guidance

2024-014: Critical Remote Code Execution Vulnerability in Jenkins ↗ source

January 30, 2024 CERT-EU Advisory

Summary

The advisory published provides detailed information on various attack scenarios, exploitation pathways, descriptions of the fixes, and potential workarounds for those unable to immediately Multiple proof-of-concept (PoC) exploits for CVE-2024-23897 are now available [2]. The vulnerability CVE-2024-23897, with a CVSS score of 9.8, could allow an unauthenticated attacker with overall/read permission to read data from arbitrary files on the Jenkins server The vulnerability CVE-2024-23898, with a CVSS score of 8,8, is a cross-site WebSocket hijacking issue where attackers could execute arbitrary CLI commands by tricking a user into clicking The exploitation of these vulnerabilities could lead to admin privilege escalation and arbitrary remote code execution under certain conditions [1]. CERT-EU recommends immediate update of affected Jenkins versions to the latest patched versions.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-23897 9.8 Critical Jenkins Jenkins Command Line Interface (CLI) Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can le…
CVE-2024-23898 8.8 High Jenkins Project Jenkins Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made throug…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.